Skip to content
COOEY
LIVE FEED
228 events · 13 sources · newest first
2026-03-09 NVD CVE
vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in the load_from_url_async method due to inconsistent URL parsing...
2026-03-07 NVD CVE
Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. The @backstage/plugin-techdocs-node package...
2026-01-27 NVD CVE
In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflow in gpg-agent during PKDECRYPT--kem=CMS handling. This can easily...
2026-01-21 NVD CVE
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without...
2026-01-20 NVD CVE
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage)...
2026-01-09 NVD CVE
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an ...
2026-01-07 NVD CVE
pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution...
2026-01-04 NVD CVE
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an improper access control vulnerability that allows unauthorized device manipulation by accepting arbitrary serial numbers without ownership...
2025-06-05 NVD CVE
A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of the component PLS Command Handler. The manipulation leads to buffer overflow. The attack can be...
2025-05-29 NVD CVE
A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This vulnerability affects unknown code of the component NLST Command Handler. The manipulation leads to buffer overflow. The...
2025-01-14 NVD CVE
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3,...
2024-11-27 NVD CVE
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series...
2024-09-10 NVD CVE
Azure Stack Hub Elevation of Privilege Vulnerability
2024-09-10 NVD CVE
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
2024-09-10 NVD CVE
Microsoft SQL Server Elevation of Privilege Vulnerability
2024-09-10 NVD CVE
An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network.
2024-09-10 NVD CVE
Windows TCP/IP Remote Code Execution Vulnerability
2024-09-10 NVD CVE
Windows Remote Desktop Licensing Service Spoofing Vulnerability
2024-09-10 NVD CVE
Microsoft SQL Server Elevation of Privilege Vulnerability
2024-09-10 NVD CVE
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
2024-08-08 NVD CVE
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix server re-repick on subrequest retry When a subrequest is marked for needing retry, netfs will call cifs_prepare_write() which will make...
2024-06-27 NVD CVE
An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
2024-04-25 NVD CVE
An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An...
2024-01-30 NVD CVE
Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the...
2023-08-08 NVD CVE
Windows System Assessment Tool Elevation of Privilege Vulnerability
2023-08-08 NVD CVE
Windows Mobile Device Management Elevation of Privilege Vulnerability
2023-07-11 NVD CVE
A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been classified as critical. This affects an unknown part of the file admin_class.php of the component Login Page. The manipulation...
2021-12-03 NVD CVE
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
ajaxnetajaxnet-professionalajaxprocisa-kevcve-2021-23758deserializationendlife
◀ PREV PAGE 06 / 06 NEXT ▶